- Products
- Learn
- Local User Groups
- Partners
- More
What's New in Check Point SASE
Wednesday, 9 September @ 5pm CET / 11am EDT
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Regarding CVE-2026-85103, to me it's not clear if gateways with VPN software blade disabled are affected too. Any ideas or further information? Thank you
This specific issue is about certificate processing, so it theoretically can be triggered in an environment even without VPN, but with VPN certificates.
This is what the CVE description says: A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.
Thanks,
At what time will the Spark SK articles be updated to show the new builds? Currently neither are showing the latest patched versions.
When is the CPLP package going to be pushed?
All the devices I've checked still have V18.
Will this package require any manual intervention for CPLP to apply the code fix to the processes?
Also why is the Jumbo for these CVEs integrated with dozens of other fixes? This should be a targeted JHF so people can install without a repeat of the recent DHCP bug.
You can manually apply the CPLP to stay on your current JHF or wait for Check Point to push it to your gateways IF you have it enabled.
Answering both questions:
1. The fixes are available immediately with LivePatch packages and can be downloaded from the SKs mentioned above or automatically through the LivePatch mechanism.
2. They are also included with JHF packages in the SKs.
You can use either way to patch.
My whole environment is still on "Urgent Take 18"...
So either something is not working in my environment, or it is a very slow staged rollout.
I assume this is done on a rollout basis and not done to everyone all at ones.
If you need to apply immediately, you can download the relevant update (Take 24) from: https://support.checkpoint.com/results/sk/sk185114
Done that in a lab.
Waiting to see if it actually armes the ready processes or not.
[Expert@FWA-01:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
vpn1:iked ready livepatch 0/0 2026-07-15 08:13:55 sk185033
vpn1:vpnd ready livepatch 0/0 2026-07-15 08:13:55 sk185033
One row per <name>:<proc> deployment (revert/status target). Use `cplp status --patch-id <name>` for live per-pid state.
[Expert@FWA-01:0]# autoupdatercli install /home/admin/urgent_security_updates_R81_20_Bundle_T24_AutoUpdate.tar
Install request of component urgent_security_updates version 24 handled. To see installation status, see logs: /opt/CPInstLog/AutoUpdater.log and /opt/CPInstLog/AutoUpdateLogs/urgent_security_updates
[Expert@FWA-01:0]# cplp list
ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:ike* armed livepatch 1/1 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:vpn* armed livepatch 1/1 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* armed livepatch 2/2 2026-09-09 15:01:30 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-09 15:01:29 CVE-2026-85102 CVE-2026-85103
vpn1:iked* jumbofix livepatch 0/0 2026-07-15 09:13:55 sk185033
vpn1:vpnd* jumbofix livepatch 0/0 2026-07-15 09:13:55 sk185033
* reports to the management audit trail (`cplp coverage disable --patch-id <name>` to stop).
[Expert@FWA-01:0]#
My guessing is that they would have been armed if you would install them:
a) on a SMS, as they are the ones with CPCA
b) if you have deployed SD-WAN - VPNRAD seems to be a part of this blade.
But maybe someone from CP stuff could confirm that?
I must say that this little known improvement - CP Live Patch - is a fantastic job from R&D!
hm...
Manually rolling that out is nearly as much effort, as doing an HFA install..
(At least the way like that is described in that SK...)
At least an "update now" flag in the cplp would be great.
Hello, where can I find the exact firmware for Spark? There are still unupdated FWs build on the site.
Thank you
It looks like the Spark download page was finally updated and shows the new Build 2325 but all the download links are still pointing to the old build 998002279. Really seems like CheckPoint should have all the download links ready to go before sending you a big e-blast about a critical vulnerability.
Now, it shows me the new build 2325. But I see that the .imgs are swapped between 2560/2570/2580/2590 and 1600/1800/1900/2000 Appliances... I have about 50 locally managed Sparks waiting for me at our customers to update. It's going to be a long night 🙂
okay, my mistake. R82 for Spark 1500 still has the original build on the download link...
Yes, 1500 was what I was attempting to download. Hopefully they fix it soon.
Looks like I found the direct link for the 1500 devices:
Still no Build 4968 for R81.10.17 in sk179615. Do I have to look in a different location?
Here, this link is referenced on the CVE sk itself
https://support.checkpoint.com/results/sk/sk183153
hello, please look here: https://support.checkpoint.com/results/sk/sk183153
None of the download links work:
https://support.checkpoint.com/results/sk/sk1000117/
https://support.checkpoint.com/results/sk/sk1000118/
https://support.checkpoint.com/results/download/145356
Also, if I click Check for Updates in the Gaia WebUI, it shows Jumbo Take 122 for R82 as being the latest available and Jumbo Take 40 as the latest available for R82.10.
I received the email notification from CheckPoint 48 minutes ago.
I double-checked; the download links are working.
The Live Patch download links work here.
I have already applied Urgent Take 24 and it works well. Better than the jumbo approach for sure.
CaseyB, that page is blank when I open (and fresh it) from the UK...
Strange. Here are the direct links (R81.20, R82, R82.10 probably not in order):
https://support.checkpoint.com/results/download/145415
https://support.checkpoint.com/results/download/145416
https://support.checkpoint.com/results/download/145417
Still not working here:
See the above screenshot...
Are you positive that these links have been made available to customers, and not just internally?
That's what I used as a customer. ¯\_(ツ)_/¯
The WebUI in Gaia is now showing the full update packages for both R82 and R82.10, so I'm using that method...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementWed 23 Sep 2026 @ 06:00 PM (EDT)
Santo Domingo: Workspace Security and SASE Live: Protección Total del Usuario Email, Endpoint y SASEAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY